Skip to content
Security specialists reviewing cyber risk and readiness data
Product

A published scoring model, not a black box.

Six modules, fixed weights, and a human sign-off on every finding. You can see exactly why your score is what it is — and what would move it.

Scoring model

How the weighted readiness score is calculated.

Each module is scored on its own evidence, then combined using the published weights below.

M-0125%

Microsoft 365 security

The heaviest reading on the panel: identity, tenant configuration and admin hygiene across the platform most SMEs actually run on.

  • MFA and conditional access coverage
  • Admin account separation and privilege review
  • Email authentication (SPF, DKIM, DMARC)
  • Sharing, guest access and data-loss settings
  • Logging, retention and alerting baseline
M-0220%

Incident readiness

Whether a real incident would be handled or improvised — roles, contacts, escalation, backups and restore confidence.

  • Documented incident plan and named roles
  • Escalation and out-of-hours contact chain
  • Backup coverage and last verified restore
  • Customer, authority and insurer notification path
  • Tabletop walk-through of one realistic scenario
M-0320%

External exposure

What the internet can see and reach. Permission-based, non-intrusive checks against your authorized scope only.

  • Internet-facing asset and domain inventory
  • Exposed services, portals and remote access
  • Certificate and DNS hygiene
  • Known credential and data leak signals
  • Written scan authorization before any test
M-0415%

AI usage risk

Which AI tools are used, what data goes into them, and which rules are missing — a rapidly evolving SME risk area.

  • Inventory of AI tools and real use cases
  • Confidential, customer and source-code data flows
  • Approval, retention and human-review practice
  • Written AI usage policy and staff guidance
  • Vendor terms and training-data settings
M-0510%

Supplier risk

Third parties with access to your systems and data — MSPs, SaaS vendors, contractors and integrators.

  • Critical supplier and access inventory
  • Contractual security and breach-notice terms
  • Offboarding and access revocation practice
  • Concentration risk on a single IT provider
M-0610%

Governance & compliance evidence

Mapping the evidence you already have against what customers, auditors and frameworks keep asking for.

  • Existing policies, owners and review dates
  • Evidence mapping for NIS2 / ISO 27001 / SOC 2 questions
  • Security responsibilities and decision rights
  • Awareness training and onboarding records

Current Cybnivo methodology — the scoring model will be refined as we validate it through pilot assessments.

Industrial option

Safe Industrial / OT readiness add-on

For manufacturing, automation and robotics SMEs. A safe, non-intrusive readiness review of industrial systems — no active testing on production lines, designed to avoid operational disruption.

Security engineer monitoring segmented industrial systems from a factory control room
Included in the annex
  • Industrial asset and network segmentation overview
  • Remote maintenance and integrator access review
  • Downtime and production-impact scenario checklist
  • Legacy machine and unsupported-system inventory
  • Handover language that engineers and management both accept

No active testing on production or safety-relevant systems — designed to avoid operational disruption.

Deliverables

What lands on the management table on day ten.

01Management summary in plain business language
02Weighted readiness score across six categories
03Prioritized top risks with business impact
0430/60/90-day remediation roadmap with owners
05Compliance evidence map (what exists, what is missing)
06Incident readiness gap list and contact chain
07Supplier and AI usage risk register
08Optional industrial/OT readiness annex

Want to see the report structure before you commit?

We will walk you through the sample report structure on the discovery call — including findings, scoring and the roadmap.

Permission-based · Reviewed before delivery